Impact
A vulnerability in AMI AptioV BIOS allows a privileged local user to trigger an "Incomplete List of Disallowed Inputs" condition. Successful exploitation can lead to arbitrary code execution, directly compromising the confidentiality, integrity, and availability of the affected system. The issue stems from a flaw in the handling of inputs to the BDS module, classified as CWE‑184. The impact is the ability for a local attacker to take full control of the machine’s firmware and subsequently the operating system.
Affected Systems
The vulnerability affects systems running AMI AptioV BIOS firmware. No specific versions are listed in the advisory, so any installation of AptioV may be susceptible until a vendor update is applied. System owners should verify their BIOS version against the latest AMI release notes.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is currently unavailable, but the lack of a KEV listing does not diminish the risk to privileged users with local access. Based on the description, it is inferred that a local attacker who can interact with the BIOS—such as a user with physical access or one who has compromised the host—can exploit the flaw. The exploit requires local privilege but does not require network connectivity or elevated OS permissions, making it particularly dangerous in environments where device access is not tightly controlled.
OpenCVE Enrichment